EP3973685B1 - Kontrolle eines physischen zugangs um zugriff zu gewähren - Google Patents

Kontrolle eines physischen zugangs um zugriff zu gewähren Download PDF

Info

Publication number
EP3973685B1
EP3973685B1 EP20731715.7A EP20731715A EP3973685B1 EP 3973685 B1 EP3973685 B1 EP 3973685B1 EP 20731715 A EP20731715 A EP 20731715A EP 3973685 B1 EP3973685 B1 EP 3973685B1
Authority
EP
European Patent Office
Prior art keywords
access
credential
authentication
beacon
physical
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
EP20731715.7A
Other languages
English (en)
French (fr)
Other versions
EP3973685C0 (de
EP3973685A1 (de
Inventor
Sylvain Jacques PREVOST
Kapil Sachdeva
Stephen Carney
Wayne PAK
Jianbo Chen
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
HID Global Corp
Original Assignee
HID Global Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by HID Global Corp filed Critical HID Global Corp
Priority to EP25151307.3A priority Critical patent/EP4513457A3/de
Publication of EP3973685A1 publication Critical patent/EP3973685A1/de
Application granted granted Critical
Publication of EP3973685C0 publication Critical patent/EP3973685C0/de
Publication of EP3973685B1 publication Critical patent/EP3973685B1/de
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/27Individual registration on entry or exit involving the use of a pass with central registration
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00309Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • G06V40/16Human faces, e.g. facial parts, sketches or expressions
    • G06V40/172Classification, e.g. identification
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00563Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys using personal physical data of the operator, e.g. finger prints, retinal images, voicepatterns
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00571Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated by interacting with a central unit
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/20Individual registration on entry or exit involving the use of a pass
    • G07C9/22Individual registration on entry or exit involving the use of a pass in combination with an identity check of the pass holder
    • G07C9/25Individual registration on entry or exit involving the use of a pass in combination with an identity check of the pass holder using biometric data, e.g. fingerprints, iris scans or voice recognition
    • G07C9/257Individual registration on entry or exit involving the use of a pass in combination with an identity check of the pass holder using biometric data, e.g. fingerprints, iris scans or voice recognition electronically
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C9/00309Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks
    • G07C2009/00412Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated with bidirectional data transmission between data carrier and locks the transmitted data signal being encrypted
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/00174Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys
    • G07C2009/00753Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated by active electrical keys
    • G07C2009/00769Electronically operated locks; Circuits therefor; Nonmechanical keys therefor, e.g. passive or active electrical keys or other data carriers without mechanical keys operated by active electrical keys with data transmission performed by wireless means
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/40Security arrangements using identity modules
    • H04W12/47Security arrangements using identity modules using near field communication [NFC] or radio frequency identification [RFID] modules
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/63Location-dependent; Proximity-dependent
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/12Messaging; Mailboxes; Announcements

Definitions

  • Embodiments illustrated and described herein generally relate to system architectures for physical access control systems.
  • Seamless access control refers to when physical access is granted to an authorized user through a controlled portal without requiring intrusive actions of the user such as entering or swiping an access card at a card reader or entering a personal identification number (PIN) or password.
  • a Physical Access Control (PAC) system is a type of system that can provide seamless access.
  • a PAC system authenticates and authorizes a person to pass through a physical access point such as a secured door. Improvements to PAC systems are described herein having innovative interplay between wireless technologies, smart phones, secure gateways and cloud infrastructure. These improvements not only enhance the security of the overall system, they also lead to a better user experience.
  • FIG. 1 is an illustration of a basic PACS structure useful for an office application.
  • the Access Credential is a data object, a piece of knowledge (e.g., PIN, password, etc.), or a facet of the person's physical being (e.g., face, fingerprint, etc.) that provides proof of the person's identity.
  • the Credential Device 104 stores the Access Credential when the Access Credential is a data object.
  • the Credential Device 104 may be a smartcard or smartphone.
  • Credential Devices include, but are not limited to, proximity radio frequency identifier (RFID) based cards, access control cards, credit cards, debit cards, passports, identification cards, key fobs, near field communication (NFC) enabled devices, mobile phones, personal digital assistants (PDAs), tags, or any other device configurable to emulate a virtual credential.
  • RFID proximity radio frequency identifier
  • NFC near field communication
  • PDAs personal digital assistants
  • the Credential Device 104 can be referred to as the Access Credential.
  • the Reader device 102 retrieves and authenticates the Access Credential when using a Credential Device and sends the Access Credential to the Access Controller 106.
  • the Access Controller 106 compares the Access Credential to an Access Control list and grants or denies access based on the comparison, such as by controlling an automatic lock on a door for example.
  • an Access Controller 106 may be included in the Reader device 102. These Reader devices can be referred to as offline readers or standalone readers. If the unlocking mechanism is included as well, a device is referred to as smart door lock which is more typically used in residential applications. Devices such as smart door locks are often battery powered, and power consumption and battery lifetime can be key parameters for the devices.
  • FIG. 2 is a block diagram of an example of a PAC system backend architecture.
  • the physical access control authorization logic is moved from a Reader device or an Access Controller local to the physical access portal to a Secure Internet of Things (IoT) Gateway (SIG) that can be remote from the physical access portal.
  • IoT Internet of Things
  • SIG Secure Internet of Things Gateway
  • the Reader devices, or Front End (FE) devices, at or near the portal location are still present, but can be simplified to basically include an antenna and a modulator/demodulator to exchange signals with Credential Devices.
  • the signals are transferred to the SIG 208 for analysis related to access control using the physical access control authorization logic.
  • the authorization logic of the SIG 208 may include an authorization engine to make the authentication decisions at a central location for access control at many remote locations.
  • the authorization engine of the SIG 208 may also manage sensor-driven identification at the remote locations.
  • the example in FIG. 2 shows FE devices 202 connected using a wired interface to an Ethernet network (or other Local Area Network, or LAN) that connects to the SIG 208.
  • the LAN may be a transmission control protocol Internet protocol TCP/IP) based network or may be an IoT mesh network.
  • the wired interface may include an RS485 to Internet Protocol (IP) translation 210.
  • the Ethernet network may include an Ethernet switch 212 for connection to the SIG 208.
  • the SIG 208 can include a WiFi physical layer for connection to a WiFi network for communication with the FE devices 202.
  • the FE devices 202 may relay credential information (e.g., PAC Reader devices) from Credential devices (e.g., RFID devices) to the SIG 208.
  • the FE devices 202 may be connected to one or more sensor devices 214 (e.g., cameras) for sensor-driven authentication.
  • the FE devices 202 may communicate with other downstream devices using Bluetooth TM Low Energy (BLE) signaling to provide additional wireless capability.
  • BLE Bluetooth TM Low Energy
  • the FE devices 202 may provide wireless capability using Long Range (LoRa) low energy network communications, Zigbee network communications, or Long Term Evolution (LTE) network communications, Ultra-Wide Band communications, Sigfox communications, etc.
  • LoRa Long Range
  • LTE Long Term Evolution
  • the FE devices 202 provide additional computing capabilities for the PAC system (e.g., an FE device may include or communicate with a graphics processing unit or GPU).
  • the FE devices 202 may include artificial intelligence (AI) (e.g., neural networks) or communicate with AI devices to provide facial recognition capability, anomaly analysis, etc.
  • AI artificial intelligence
  • the FE modules may extend storage capabilities of the SIG 208 (e.g., by storing access logs or other access data).
  • FIG. 3 is an example of a layer model of a SIG 308.
  • the SIG 308 includes physical layer circuitry 320 for accessing WiFi, Ethernet, or RS485 interfaces to communicate with downstream FE devices.
  • the SIG 308 includes an array of secure elements 322. The number of secure elements 322 in the array depends on the load balancing requirements of remote FE devices (e.g., Reader devices).
  • the secure elements 322 are used to exchange credential information with Credential devices and can enhance security to the transfer of communication for the physical access.
  • the secure elements 322 may store cryptographic keys for secure transmission and reception of sensitive data and may perform authentication of Credential devices and users of the devices.
  • the secure elements 322 are Hardware Security Modules (HSMs).
  • the Reader devices may be used in a transparent mode in which they wirelessly relay information between the Credential devices and the secure elements 322 of the SIG 308.
  • the Reader devices may not provide any analysis of the information being relayed and would not be aware of any logical need for communication between the SIG 308 and the Credential devices.
  • One of the secure elements 322 may be allocated for each authentication session.
  • the connectivity between the Reader device and a SIG backend can be either direct (e.g., LAN) or indirect (e.g., via a gateway/controller).
  • the SIG 308 also includes a Trusted Platform Module (TPM) 324.
  • the TPM 324 is a type of secure hardware element sometimes used in system on chip (SoC) devices. Including the TPM in the SIG 308 complements the secure elements 322 by enabling the secure bootstrap of the SIG 308 and providing secure primitives to the applications running on the SIG 308.
  • the SIG 308 also includes processing circuitry 326 and memory storage.
  • the SIG 308 may include a server remote from the access portals it controls.
  • the SIG 308 may include additional physical layers 328 for communicating upstream to devices in the system backend.
  • FIG. 4 is a block diagram of an example of a software architecture of a SIG 408.
  • the SIG 408 includes processing circuitry (e.g., one or more processors) executing instructions included in the software to perform the functions described.
  • the processing circuitry and software of the SIG 408 implement an Authentication Engine 430 as a central source to make the authentication decisions. Changing the authentication logic of the Authentication Engine 430 changes the access policy for all of the physical access portals.
  • a Security Service 432 provides load balancing of the authentication sessions being performed by the secure elements 422.
  • the Security Service 432 may cause the secure element to open and manage a secure channel with an access credential device.
  • the SIG 408 includes a Sensors Access Service 434 to process the information (e.g., sensor data) coming from authentication sensors 414.
  • the authentication sensors 414 may include cameras that provide video streams for authentication (e.g., by facial recognition).
  • the Sensors Access Service 434 processes the sensor information and the SIG 408 may include authentication applications 436 or "Apps" to perform authentication using the information provided by the sensors.
  • the Authentication Engine 430 needs to authenticate a person. This can require different methodologies than those used by electronic devices to authenticate another electronic device. Authentication methods for persons can be split into four broad categories: authentication by "Who you are” which can be determined by face, fingerprint, or other biometric, “What do you have” which can be determined by a credential device, "What do you know” which can be determined by a password or PIN, and "Where you are” which can be determined by proof of presence and proof of intent to access.
  • Sensors and credential devices can be used to seamlessly authenticate a person for access.
  • Sensors can be used for close range detection and authentication (e.g., 3 meters or less) using biometrics such as facial recognition, gait analysis, etc.
  • Credential devices such as smartphones or smartcards can be used for longer range (e.g., up to around 15 meters) detection and authentication.
  • FIG. 5 is a diagram of an example of a PAC system that authenticates access using a smartphone.
  • the access control portal is a turnstile 540.
  • the smartphone 542 emits a low energy level beacon signal in a low energy broadcast mode.
  • the smartphone 542 may support background Bluetooth TM Low Energy (BLE) advertising when the smartphone is configured as a Bluetooth TM peripheral device.
  • BLE is only an example and other wireless protocols either long range or short range can be used.
  • the term beacon is intended to include all wireless signals that can potentially serve the functions of the beacon described herein.
  • the beacon signal is detected using a beacon reader device 544 or beacon detector of the PAC system.
  • the beacon reader device 544 sends notice of the beacon detection to a seamless access authentication device 508 (e.g., a SIG device, or a backend server).
  • the beacon reader device 544 may send a message indicating beacon detection via the cloud 510 (e.g., using a cloud-based messaging service).
  • cloud is used herein to refer to a hardware abstraction. Instead of one dedicated server processing messages or routing messages, the messages can be sent to a file data center or processing center. The actual server used for the processing and routing may be interchangeable at the data center or processing center.
  • the notice of the detected beacon signal can be sent to the authentication device 508 using a WiFi network of the PAC system instead of the cloud.
  • the notice of the detected beacon signal can be sent to the authentication device 508 using other networking systems (e.g., IoT mesh networks) if for example the WiFi network and cloud are unavailable.
  • the authentication device 508 triggers the sending of a cloud-based message to the smartphone 542.
  • the cloud-based message is received by the smartphone and an App of the smartphone 542 can be activated.
  • the cloud-based messaging should reliably waken or enable the smartphone 542 from a low power mode (e.g., a sleep mode) to an active mode.
  • a low power mode e.g., a sleep mode
  • "Reliably” means that an exchange or transfer of information is performed regardless of the state of the applications in the smartphone (e.g., sleep mode, deep-sleep mode, background or foreground applications).
  • the authentication device 508 may initiate a secure session with the smartphone for transfer of authentication information with the smartphone 542. Secure communications may be established between the smartphone 542 and a secure element of the authentication device 508. The secure communications may be via the cloud 510. The secure element may share a temporary session key (e.g., using a security token service or STS seed) with the smartphone 542. The secure communications retrieve the access credential information from the smartphone 542. After successful authentication of the access credential information, the authentication device 508 may transmit information (e.g., via Ethernet or other LAN) to an access controller 548 to allow access or the authentication device 508 may deny access.
  • information e.g., via Ethernet or other LAN
  • the authentication device 508 is a Reader device that includes authentication capability.
  • the secure communication channel may be a BLE communication channel, WiFi channel, or other radio frequency (RF) communication channel established between the Reader device and the smartphone 542, and the Reader device includes the authentication logic to authenticate the access credential.
  • the Reader device communicates with the access controller 548 to allow access or deny access.
  • the Reader device is a Reader/Control device and no communication needs to be sent to grant or deny access. Instead, the Reader/Control device itself directly grants or denies access according to the authentication operation.
  • FIG. 6 is a diagram of another example of a PAC system that authenticates access using a smartphone 642.
  • the access control portal is again a turnstile 640.
  • the smartphone 642 does not broadcast a beacon for detection by a beacon reader. Instead, the smartphone 642 is enabled in a read mode or scan mode to look for a beacon signal from a beacon transmitting device 650 positioned in the vicinity of the controlled access portal.
  • the smartphone 642 may support background BLE scanning when the smartphone is configured as a Bluetooth TM central device. Applications of the smartphone 642 may be activated or wakened when a specific data pattern is detected within a specific timing window.
  • the smartphone 642 sends a communication to the authentication device 608 to begin an authentication session.
  • the communication may be sent to the authentication device 608 via the cloud 646.
  • the authentication device 608 may then initiate a secure session with the smartphone 642 to exchange authentication information with the smartphone 642.
  • Secure communications may be established between the smartphone 642 and a secure element of the authentication device 608 via the cloud 646 to retrieve the access credential.
  • the authentication device 608 may transmit information to the access controller 648 to allow access or the authentication device 608 may deny access.
  • the authentication device 608 may be configured to communicate with either read mode smartphones or broadcast mode smartphones, so that one authentication device 608 may service multiple controlled access portals that may use either type of communication technique.
  • the authentication device 608 may be a Reader device that includes authentication capability.
  • the Reader device may open a secure communication channel with the smartphone 642 to retrieve the access credential in response to the communication from the smartphone 642.
  • the Reader device authenticates the access credential and communicates with the access controller 648 to allow access or deny access, or the Reader device can be a Reader/Control device that directly grants or denies access according to the authentication operation.
  • sensors can be used for closer range detection and authentication.
  • An example of a sensor is the camera 552, 652 shown in the PAC system examples of FIGS. 5 and 6 .
  • Sensor data can be transferred to an authentication device using an FE device and a SIG device as in the example of FIG. 2 , or the authentication device may be a Reader device located near the sensor to receive the sensor data directly.
  • the sensors provide sensor data (e.g., video image data or a video stream of video data if the sensor is a camera) used to determine one or more biometric identifiers for authentication of the person looking to gain access through the portal.
  • the authentication device granting or denying access to the person is a SIG remote from the access portal and sensor data is provided to a Sensor Access Service of the SIG.
  • An authentication engine of the authentication device authenticates the person using the biometric identifiers.
  • the authentication device is a Reader device in the proximity of the physical access portal and the Reader device authenticates one or more biometric identifiers of the person.
  • the biometric identifiers can include facial recognition from video data generated by a sensor device.
  • the data obtained from the sensor can be compared to a biometric database.
  • the data base may be stored in memory of a server of the system backend.
  • the biometric database may include multiple angles and poses of individuals that may be allowed access through the physical access portal.
  • the angles and poses may be from images (e.g., photos) of the person taken during enrollment of the person as an employee.
  • the multiple angles and poses are useful to match biometric even though the person may approach the sensor from different angles.
  • the angle or pose of the person in the sensor data can be matched to the stored biometric angle or pose.
  • the authentication engine may perform AI algorithms (e.g., a neural network algorithm) to implement the facial recognition.
  • Anti-spoofing measures can be applied to augment the facial recognition biometric.
  • the video data can be used to estimate the height of the person.
  • the authentication engine may measure the distance between eyes of the person and estimate the distance away from the sensor. The height of the person approaching can be estimated based on the top of the person's head and the distance between the eyes and the distance away from the sensor. The authentication engine may compare the estimated height to a recorded height for the individual as an added biometric to the facial recognition. Access through the physical portal may be granted based on the combined results of the biometric analysis.
  • the video data can be used to analyze the gait of the person as a biometric to augment facial recognition.
  • the authentication engine may perform gait analysis to determine if the gait biometric of the person matches a recorded gait of the person identified by the facial recognition.
  • the authentication engine may analyze shadows included in a video stream.
  • the authentication operation can include analyzing the video stream to detect shadows that don't move with respect to facial features. If the shadows don't move as expected, this may indicate that a photo or other still image may be being used to spoof the seamless access appliance. Background images can be used similarly.
  • the authentication operation can include analyzing the background of the video stream to determine if the background is moving appropriately with the change in location of the face.
  • the person's apparel in the image can be compared to the day-to-day habits of the person to determine if the person's present appearance is in line with person's usual appearance.
  • the augmented biometrics may only be used when the facial recognition does not provide sufficient results. For example, there may be a correlation measurement included in the facial recognition that indicates how strongly the face in the video data matches the stored facial recognition data. The correlation measurement must meet a threshold correlation or else additional biometric measurements are used. Other non-biometric information can also be used. For example, the authentication device may check a tentatively identified person's work schedule to confirm that the identified person should be seeking the physical access.
  • Electromagnetic signature of a person day-to-day could be analyzed.
  • Electromagnetic signals such as BLE or WiFi signals emitted from devices (e.g., mobile devices, phones, tablets, laptops, smartwatches, etc.) commonly carried by a person can be monitored day-to-day.
  • This electromagnetic signature may change if the person is carrying more devices or different devices than usual. This change may indicate that the person is not authentic.
  • the seamless access device may require some action of the user to complete the authentication, such as by entering a password on a keypad or using a smartphone.
  • Results of the facial recognition analysis and confirmation using secondary analysis can be used for machine learning of AI algorithms to improve the facial recognition.
  • authentication with sensor data and badge or smartphone credential authentication can be paired together for a two-factor authentication.
  • an authentication device could first authenticate a person a longer distance from the physical access portal based on credential information sent by the person's smartphone. Shorter range sensor-based authentication (e.g., facial recognition) could follow when the person is within range.
  • This approach provides an authentication technique that matches the access credential with the biometric identification of the person. Detection of the presence of the credential device (e.g., through beacon signaling) may trigger authentication using sensors.
  • authentication with the sensor data is performed first followed by authentication using a badge or smartphone. This allows the results of the biometric authentication to be checked using the access credential if the results of the authentication are not sufficient.
  • the processing circuitry of an authentication device can include an intent detection engine.
  • the intent detection engine uses the sensor data to determine that the person intends to pass through a physical access portal.
  • the authentication device that includes the intent detection engine may be remotely located from the physical access portal (e.g., a SIG device) and the sensor data is sent to the authentication device from a front end device, or the authentication device may be located near the physical access portal (e.g., a reader device).
  • the physical access portal includes multiple access portions, such as for example a secured double door.
  • the intent detection engine determines which of the doors the person intends to enter and only opens that door, leaving the other door closed. For example, a camera may be positioned for each door. The intent detection engine may use video image data from each of the doors and compare the movement of the person in the two images to determine which of the doors the person intends to enter. The intent detection engine may compute a score for intent for each door and open the door with the highest resulting score.
  • one or more magnetometer sensors or accelerometer sensors could be positioned by each door to detect which door the person intends to enter based on signals from the sensors.
  • the sensors are located in the smartphone of the person and the intent detection engine detects movement of the smartphone to deduce intent of the person.
  • seamless access control There can be security issues involved with seamless access control. For example, a seamless physical access system that opens the door when an authorized user is within two meters may allow multiple persons to enter instead of only the credentialed user when another person (authorized or not authorized) is close behind or "tailgating" the credentialed user.
  • Sensor data can be used to detect tailgating. If two persons are passing through the physical access portal close together, the authentication device may use facial recognition to authenticate both persons. If both persons pass authentication, the authentication device may do nothing. If the trailing person does not pass authorization, the authorization device may send an alert to the leading person (e.g., to the person smart phone) or send an alert or alarm to a security entity.
  • users may carry beacon emitting badges and the authentication device can detect the number of people attempting to enter from the beacon signals emitted by the badges. Detection of tailgating can occur after the fact by detecting number of people within the secured space and comparing that number to the number of people logged as entering. For example, the number of people in the space can be determined using video data sent to the authentication device from one or more cameras.
  • FIG. 7 is a flow diagram of a method 700 of operating a seamless PAC system.
  • access credential information from a credential device is received by an authentication device of the PAC system.
  • the credential information may be a data object that provides proof of the identity of the user of the credential device for access through a physical portal controlled by the PAC system.
  • the credential information is received by the authentication device via a radio access network using a cloud-based messaging service.
  • the authentication device sends an activation message to the credential device using the cloud-based messaging service in response to detection of a beacon signal from the credential device.
  • the beacon may be detected using a beacon reader device of the PAC system.
  • the credential device sends the credential information in response to detecting a beacon signal transmitted by the PAC system.
  • the beacon signal may be transmitted by a beacon transmitting device of the PAC system.
  • the access credential information is authenticated using the authentication device.
  • the credential information may be compared to authorization database stored by the authentication device, and the user is authorized when the credential information matches data for authorized users.
  • access is granted when the credential information indicates that the user of the credential device is authorized for access and access is denied otherwise.
  • the authentication device authenticates the user using biometric information.
  • Sensor devices located near the physical access portal collect sensor data for the user.
  • the sensor data is compared to biometric data for authorized users. Access is granted when the sensor data and credential data indicate that the user is an authorized user.
  • FIG. 8 is a block diagram schematic of various example components of an authentication device for supporting the device architectures described and illustrated herein.
  • the device 800 of FIG. 8 could be, for example, an authentication device that analyzes evidence of authority, status, rights, and/or entitlement to privileges for a holder of a credential device.
  • a credential device can be a portable device having memory, storing one or more user credentials or credential data, and an interface (e.g., one or more antennas and Integrated Circuit (IC) chip(s)), which permit the credential device to exchange data with another device, such as an authentication device.
  • IC Integrated Circuit
  • One example of credential device is an RFID smartcard that has data stored thereon allowing a holder of the credential device to access a secure area or asset protected by a reader device.
  • Another example of a credential device is a smartphone that has the data stored in memory.
  • examples of an authorization or authentication device 800 for supporting the device architecture described and illustrated herein may generally include one or more of a memory 802, a processor 804, one or more antennas 806, a communication module 808, a network interface device 810, a user interface 812, and a power source 814 or power supply.
  • Memory 802 can be used in connection with the execution of application programming or instructions by processor 804, and for the temporary or long-term storage of program instructions or instruction sets 816, authorization data 818, such as credential data, credential authorization data, or access control data or instructions, as well as any data, data structures, and/or computer-executable instructions needed or desired to support the above-described device architecture.
  • memory 802 can contain executable instructions 816 that are used by the processor 804 to run other components of device 800, to make access determinations based on credential or authorization data 818, and/or to perform any of the functions or operations described herein, such as the method of FIG. 7 for example.
  • Memory 802 can comprise a computer readable medium that can be any medium that can contain, store, communicate, or transport data, program code, or instructions for use by or in connection with device 800.
  • the computer readable medium can be, for example but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device.
  • suitable computer readable medium include, but are not limited to, an electrical connection having one or more wires or a tangible storage medium such as a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), Dynamic RAM (DRAM), any solid-state storage device, in general, a compact disc read-only memory (CD-ROM), or other optical or magnetic storage device.
  • Computer readable media includes, but is not to be confused with, computer readable storage medium, which is intended to cover all physical, non-transitory, or similar embodiments of computer readable media.
  • Processor 804 can correspond to one or more computer processing devices or resources.
  • processor 804 can be provided as silicon, as a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), any other type of Integrated Circuit (IC) chip, a collection of IC chips, or the like.
  • processor 804 can be provided as a microprocessor, Central Processing Unit (CPU), or plurality of microprocessors or CPUs that are configured to execute instructions sets stored in an internal memory 820 and/or memory 802.
  • Antenna 806 can correspond to one or multiple antennas and can be configured to provide for wireless communications between device 800 and another device.
  • Antenna(s) 806 can be arranged to operate using one or more wireless communication protocols and operating frequencies including, but not limited to, the IEEE 802.15.1, Bluetooth, Bluetooth Low Energy (BLE), near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, RF, UWB, and the like.
  • antenna 806 may include one or more antennas arranged to operate using UWB for in band activity/communication and Bluetooth (e.g., BLE) for out-of-band (OOB) activity/communication.
  • BLE Bluetooth Low Energy
  • OOB out-of-band
  • any RFID or personal area network (PAN) technologies such as the IEEE 802.15.1, near field communications (NFC), ZigBee, GSM, CDMA, Wi-Fi, etc., may alternatively or additionally be used for the OOB activity/communication described herein.
  • PAN personal area network
  • Device 800 may additionally include a communication module 808 and/or network interface device 810.
  • Communication module 808 can be configured to communicate according to any suitable communications protocol with one or more different systems or devices either remote or local to device 800.
  • Network interface device 810 includes hardware to facilitate communications with other devices over a communication network utilizing any one of a number of transfer protocols (e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.).
  • transfer protocols e.g., frame relay, internet protocol (IP), transmission control protocol (TCP), user datagram protocol (UDP), hypertext transfer protocol (HTTP), etc.
  • Example communication networks can include a local area network (LAN), a wide area network (WAN), a packet data network (e.g., the Internet), mobile telephone networks (e.g., cellular networks), Plain Old Telephone (POTS) networks, wireless data networks (e.g., IEEE 802.11 family of standards known as Wi-Fi, or IEEE 802.16 family of standards known as WiMax), IEEE 802.15.4 family of standards, and peer-to-peer (P2P) networks, among others.
  • network interface device 810 can include an Ethernet port or other physical jack, a Wi-Fi card, a Network Interface Card (NIC), a cellular interface (e.g., antenna, filters, and associated circuitry), or the like.
  • network interface device 810 can include a plurality of antennas to wirelessly communicate using at least one of single-input multiple-output (SIMO), multiple-input multiple-output (MIMO), or multiple-input single-output (MISO) techniques.
  • SIMO single-input multiple-output
  • MIMO multiple-input multiple-output
  • MISO multiple-input single-output
  • one or more of the antenna 806, communication module 808, and/or network interface device 810 or subcomponents thereof may be integrated as a single module or device, function or operate as if they were a single module or device, or may comprise of elements that are shared between them.
  • User interface 812 can include one or more input devices and/or display devices. Examples of suitable user input devices that can be included in user interface 812 include, without limitation, one or more buttons, a keyboard, a mouse, a touch-sensitive surface, a stylus, a camera, a microphone, etc. Examples of suitable user output devices that can be included in user interface 812 include, without limitation, one or more LEDs, an LCD panel, a display screen, a touchscreen, one or more lights, a speaker, etc. It should be appreciated that user interface 812 can also include a combined user input and user output device, such as a touch-sensitive display or the like. Alarm circuit 826 may provide an audio signal to a speaker or may activate a light or present an alarm condition using a display device.
  • Power source 814 can be any suitable internal power source, such as a battery, capacitive power source or similar type of charge-storage device, etc., and/or can include one or more power conversion circuits suitable to convert external power into suitable power (e.g., conversion of externally-supplied AC power into DC power) for components of the device 800.
  • suitable power e.g., conversion of externally-supplied AC power into DC power
  • Device 800 can also include one or more interlinks or buses 822 operable to transmit communications between the various hardware components of the device.
  • a system bus 822 can be any of several types of commercially available bus structures or bus architectures.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Human Computer Interaction (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Multimedia (AREA)
  • Theoretical Computer Science (AREA)
  • Oral & Maxillofacial Surgery (AREA)
  • Biomedical Technology (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Steering Control In Accordance With Driving Conditions (AREA)
  • Steering-Linkage Mechanisms And Four-Wheel Steering (AREA)
  • Lock And Its Accessories (AREA)
  • Pinball Game Machines (AREA)

Claims (14)

  1. Physisches Zugriffssteuerungs-, PAC-, System, aufweisend:
    eine Authentifizierungsvorrichtung (508), aufweisend:
    eine Schaltung (320) einer physikalischen Schicht, die dafür ausgelegt ist, elektrische Hochfrequenzsignale mit einem Funkzugangsnetz zu übermitteln und zu empfangen;
    eine Verarbeitungsschaltung (326), die mit der Schaltung (320) einer physikalischen Schicht in Wirkverbindung steht und eine Authentifizierungs-Engine (430) umfasst, die ausgelegt ist zum:
    Empfangen von in einer Berechtigungsvorrichtung (104) gespeicherten Zugriffsberechtigungsinformationen von der Berechtigungsvorrichtung (104) über das Funkzugangsnetz unter Verwendung eines cloudbasierten Nachrichtenaustauschs;
    Authentifizieren der Zugriffsberechtigungsinformationen unter Verwendung der Authentifizierungsvorrichtung (508); und
    Gewähren, der Berechtigungsvorrichtung, des Zugriffs auf ein physisches Zugriffsportal gemäß den Zugriffsberechtigungsinformationen; wobei
    das System darüber hinaus eine Beacon-Lesevorrichtung (544) aufweist, die dafür ausgelegt ist, ein Beacon-Signal zu erfassen, das durch die Berechtigungsvorrichtung (104) übermittelt wird, und eine Beacon-Erfassungsmitteilung an die Authentifizierungsvorrichtung (508) als Reaktion auf die Erfassung des Beacon-Signals zu übermitteln;
    wobei die Verarbeitungsschaltung (326) der Authentifizierungsvorrichtung (508) darüber hinaus ausgelegt ist zum:
    Initiieren der Übertragung einer Aktivierungsmitteilung an die Berechtigungsvorrichtung (104) unter Verwendung des cloudbasierten Nachrichtenaustauschsystems als Reaktion auf die Beacon-Erfassungsmitteilung; und
    Empfangen der Zugriffsberechtigungsinformationen von der Berechtigungsvorrichtung (104) über den cloudbasierten Nachrichtenaustausch.
  2. System nach Anspruch 1, wobei die Beacon-Lesevorrichtung (544) dafür ausgelegt ist, ein Bluetooth-Niedrigenergie-, BLE-, Beacon-Signal zu erfassen, das durch die Berechtigungsvorrichtung (104) übermittelt wird.
  3. System nach einem der Ansprüche 1 bis 2, aufweisend:
    eine Beacon-Übermittlungsvorrichtung (650), die dafür ausgelegt ist, ein Beacon-Signal zu übermitteln, das durch die Berechtigungsvorrichtung (104) erfassbar ist; und
    wobei die Verarbeitungsschaltung (326) der Authentifizierungsvorrichtung (508) darüber hinaus dafür ausgelegt ist, eine Anforderung zum Eröffnen einer Kommunikationssitzung von der Berechtigungsvorrichtung (104) zu empfangen und während der Kommunikationssitzung die Zugriffsberechtigungsinformationen zu empfangen.
  4. System nach einem der Ansprüche 1 bis 3, aufweisend:
    eine oder mehrere Sensorvorrichtungen (214), die dafür ausgelegt sind, Sensordaten zu erzeugen, die mit einem Benutzer der Berechtigungsvorrichtung (104) verknüpft sind, und die Sensordaten über ein lokales Netzwerk, LAN, der Authentifizierungsvorrichtung (508) bereitzustellen;
    einen Speicher, der dafür ausgelegt ist, biometrische Informationen zu speichern; und
    wobei die Authentifizierungs-Engine dafür ausgelegt ist, die Identität des Benutzers der Berechtigungsvorrichtung (104) durch Vergleichen der Sensordaten mit den biometrischen Informationen zu bestätigen.
  5. System nach Anspruch 4,
    wobei die Verarbeitungsschaltung (326) der Authentifizierungsvorrichtung (508) eine Absichtserfassungs-Engine aufweist, die dafür ausgelegt ist, eine Absicht eines physischen Zugriffs des Benutzers der Berechtigungsvorrichtung (104) unter Verwendung der Sensordaten festzustellen; und
    wobei die Authentifizierungsvorrichtung (508) dafür ausgelegt ist, den Zugriff auf das physische Zugriffsportal gemäß den Zugriffsberechtigungsinformationen und der festgestellten Absicht eines physischen Zugriffs des Benutzers der Berechtigungsvorrichtung (104) zu gewähren.
  6. System nach Anspruch 5, aufweisend:
    eine Steuerung, die zum Eröffnen eines ersten Abschnitts von mehreren Abschnitten des physischen Zugriffsportals gemäß der Absicht eines physischen Zugriffs des Benutzers der Berechtigungsvorrichtung (104) ausgelegt ist.
  7. Verfahren zum Betreiben eines physischen Zugriffssteuerungs-, PAC-, Systems, wobei das Verfahren umfasst:
    Empfangen, durch eine Authentifizierungsvorrichtung (508) des PAC-Systems, von in einer Berechtigungsvorrichtung gespeicherten Zugriffsberechtigungsinformationen von einer Berechtigungsvorrichtung (104) über ein Funkzugangsnetz unter Verwendung eines cloudbasierten Nachrichtenaustauschs;
    Authentifizieren der Zugriffsberechtigungsinformationen unter Verwendung der Authentifizierungsvorrichtung (508);
    Gewähren, der Berechtigungsvorrichtung, des Zugriffs auf ein physisches Zugriffsportal des PAC-Systems durch die Authentifizierungsvorrichtung (508) gemäß den Zugriffsberechtigungsinformationen;
    Empfangen, durch die Authentifizierungsvorrichtung (508), einer Beacon-Erfassungsmitteilung von einer Beacon-Lesevorrichtung (544) des PAC-Systems, wobei die Beacon-Erfassungsmitteilung die Erfassung einer Berechtigungsvorrichtung (104) anzeigt;
    Initiieren, durch eine Verarbeitungsschaltung (326) der Authentifizierungsvorrichtung (508), der Übertragung einer Aktivierungsmitteilung an die Berechtigungsvorrichtung (104) unter Verwendung des cloudbasierten Nachrichtenaustauschsystems als Reaktion auf die Beacon-Erfassungsmitteilung; und
    Empfangen der Zugriffsberechtigungsinformationen von der Berechtigungsvorrichtung (104) über den cloudbasierten Nachrichtenaustausch.
  8. Verfahren nach Anspruch 7, umfassend:
    Senden einer Aktivierungsmitteilung zum Aufwecken der Berechtigungsvorrichtung (104) aus einem Energiesparmodus unter Verwendung des cloudbasierten Nachrichtenaustauschs als Reaktion auf die Beacon-Erfassungsmitteilung; und
    Empfangen der Berechtigungsinformationen in einer sich anschließenden cloudbasierten Kommunikation mit der Berechtigungsvorrichtung (104).
  9. Verfahren nach Anspruch 8, umfassend:
    Erfassen, durch die Beacon-Lesevorrichtung (544), eines Niedrigenergie-Beacons eines Smartphones, das als Bluetooth-Peripheriegerät betrieben wird;
    Übermitteln, durch die Beacon-Lesevorrichtung (544), der Beacon-Erfassungsmitteilung an die Authentifizierungsvorrichtung (508) als Reaktion auf das Erfassen des Niedrigenergie-Beacons; und
    wobei das Senden der Aktivierungsmitteilung an die Berechtigungsvorrichtung (104) umfasst, die Aktivierungsmitteilung an das Smartphone zu senden.
  10. Verfahren nach einem der Ansprüche 7 bis 9, umfassend:
    Übermitteln eines Beacons unter Verwendung einer Beacon-Übermittlungsvorrichtung (650) des PAC-Systems;
    Empfangen, durch die Authentifizierungsvorrichtung (508) über den cloudbasierten Nachrichtenaustausch, einer Anforderung von einer Berechtigungsvorrichtung (104) zum Eröffnen einer Kommunikationssitzung; und
    Empfangen der Berechtigungsinformationen in einem sich anschließenden cloudbasierten Nachrichtenaustausch mit der Berechtigungsvorrichtung (104).
  11. Verfahren nach Anspruch 10,
    wobei das Übermitteln des Beacon umfasst, ein Bluetooth-Niedrigenergie-Beacon zu übermitteln; und
    wobei das Empfangen der Anforderung umfasst, die Anforderung zum Eröffnen der Kommunikationssitzung von einem Smartphone zu empfangen, das als Bluetooth-Hauptgerät betrieben wird.
  12. Verfahren nach einem der Ansprüche 7 bis 11, umfassend:
    Empfangen, durch die Authentifizierungsvorrichtung (508), von Sensordaten von einem oder mehreren Sensoren (414) über ein lokales Netzwerk, LAN;
    Authentifizieren eines Benutzers der Berechtigungsvorrichtung (104) für den Zugriff durch das physische Portal durch Vergleichen der Sensordaten mit biometrischen Daten; und
    wobei das Gewähren oder Verweigern des Zugriffs umfasst, den Zugriff auf das physische Portal durch die Authentifizierungsvorrichtung (508) gemäß den Zugriffsberechtigungsinformationen und den Sensordaten zu gewähren oder zu verweigern.
  13. Verfahren nach Anspruch 12, wobei das Gewähren oder Verweigern des Zugriffs umfasst, den Zugriff auf das physische Portal unter Verwendung einer Steuerung an dem physischen Zugriffsportal gemäß der Authentifizierung durch eine Authentifizierungsvorrichtung (508) zu steuern, die sich fernab des physischen Zugriffsportals befindet und eine Authentifizierungsrichtlinie umfasst.
  14. Verfahren nach Anspruch 12 oder 13, umfassend:
    Verwenden der Sensordaten zum Feststellen einer Zugriffsabsicht eines Benutzers der Berechtigungsvorrichtung (104); und
    Öffnen eines ersten Abschnitts von mehreren Abschnitten des physischen Zugriffsportals unter Verwendung einer Steuerung des PAC-Systems gemäß der festgestellten Zugriffsabsicht des Benutzers der Berechtigungsvorrichtung (104).
EP20731715.7A 2019-05-21 2020-05-20 Kontrolle eines physischen zugangs um zugriff zu gewähren Active EP3973685B1 (de)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP25151307.3A EP4513457A3 (de) 2019-05-21 2020-05-20 Plc zur physischen zugangskontrolle für physischen zugang

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US201962850802P 2019-05-21 2019-05-21
PCT/US2020/033768 WO2020236912A1 (en) 2019-05-21 2020-05-20 Physical access control systems and methods

Related Child Applications (2)

Application Number Title Priority Date Filing Date
EP25151307.3A Division EP4513457A3 (de) 2019-05-21 2020-05-20 Plc zur physischen zugangskontrolle für physischen zugang
EP25151307.3A Division-Into EP4513457A3 (de) 2019-05-21 2020-05-20 Plc zur physischen zugangskontrolle für physischen zugang

Publications (3)

Publication Number Publication Date
EP3973685A1 EP3973685A1 (de) 2022-03-30
EP3973685C0 EP3973685C0 (de) 2025-02-19
EP3973685B1 true EP3973685B1 (de) 2025-02-19

Family

ID=71070020

Family Applications (2)

Application Number Title Priority Date Filing Date
EP25151307.3A Pending EP4513457A3 (de) 2019-05-21 2020-05-20 Plc zur physischen zugangskontrolle für physischen zugang
EP20731715.7A Active EP3973685B1 (de) 2019-05-21 2020-05-20 Kontrolle eines physischen zugangs um zugriff zu gewähren

Family Applications Before (1)

Application Number Title Priority Date Filing Date
EP25151307.3A Pending EP4513457A3 (de) 2019-05-21 2020-05-20 Plc zur physischen zugangskontrolle für physischen zugang

Country Status (9)

Country Link
US (2) US12254732B2 (de)
EP (2) EP4513457A3 (de)
JP (3) JP7274613B2 (de)
KR (2) KR20240105515A (de)
CN (2) CN114679916B (de)
AU (4) AU2020280017B2 (de)
CA (1) CA3138776A1 (de)
MX (1) MX2021014188A (de)
WO (1) WO2020236912A1 (de)

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20240105515A (ko) 2019-05-21 2024-07-05 에이치아이디 글로벌 코포레이션 물리적 액세스 제어 시스템 및 방법
WO2022101405A2 (en) 2020-11-13 2022-05-19 Assa Abloy Ab Secure element arrays in internet-of-things systems
US20220254212A1 (en) * 2021-02-09 2022-08-11 Latch, Inc. Systems and techniques to provide smart access capabilities in a smart system environment
US11783649B2 (en) * 2021-08-24 2023-10-10 Wai Kin CHEUNG Cloud door lock control system with identification of time varied 2D codes
US20230140578A1 (en) * 2021-10-29 2023-05-04 Carrier Corporation Systems and methods for managing access points authentication requirements
US11804091B2 (en) * 2022-02-14 2023-10-31 Wai Kin CHEUNG Cloud door lock control system with identification of time varied 2D codes and images
EP4443399A1 (de) * 2023-04-03 2024-10-09 Volvo Car Corporation Zugangsverifizierungssystem und -verfahren für fahrzeug und fahrzeug
US12205424B1 (en) * 2024-04-10 2025-01-21 Yuanji Zhu Systems and methods for managing door access using movement and pose
EP4734083A1 (de) * 2024-10-22 2026-04-29 Nxp B.V. Zugangsvorrichtung und betriebsverfahren

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10185921B1 (en) * 2015-06-29 2019-01-22 Good2Go, Inc. Facility and resource access system

Family Cites Families (40)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPS6349802Y2 (de) 1986-06-25 1988-12-21
JP4698211B2 (ja) 2003-12-15 2011-06-08 株式会社リコー 情報処理装置、画像形成装置、電子データの移動の取り消し方法
WO2007010333A1 (en) 2005-07-20 2007-01-25 Hani Girgis Host security module using a collection of smartcards
JP2008099087A (ja) 2006-10-13 2008-04-24 Sony Corp 情報記録再生プログラム、情報処理装置、および情報記録再生方法
EP2053774B1 (de) 2007-10-23 2013-05-08 Nokia Siemens Networks Oy Verfahren und Vorrichtung zur Datenverarbeitung und Kommunikationssystem mit einer derartigen Vorrichtung
JP4960896B2 (ja) 2008-01-28 2012-06-27 株式会社リコー 画像形成装置及びデータ管理方法
WO2010048350A1 (en) 2008-10-21 2010-04-29 Habraken G Wouter Card credential method and system
US20100201536A1 (en) * 2009-02-10 2010-08-12 William Benjamin Robertson System and method for accessing a structure using a mobile device
EP2437193A1 (de) 2010-09-09 2012-04-04 Simulity Labs Ltd SAM-Array
BR112014004374B1 (pt) 2011-08-30 2021-09-21 Simplytapp, Inc Método para participação com base em aplicação segura em um processo de autorização de transação de cartão de pagamento por um dispositivo móvel, sistema para participação com base em aplicação segura por um dispositivo móvel em interrogações de ponto de venda
EP2677790B8 (de) 2012-06-21 2019-03-27 Telefonaktiebolaget LM Ericsson (publ) NFC-System mit einer Vielzahl an sicheren Elementen
JP6054767B2 (ja) 2013-02-19 2016-12-27 トヨタホーム株式会社 セキュリティシステム
US9148416B2 (en) 2013-03-15 2015-09-29 Airwatch Llc Controlling physical access to secure areas via client devices in a networked environment
EP3025270A1 (de) * 2013-07-25 2016-06-01 Nymi inc. Tragbare und vorautorisierte biometrische vorrichtung sowie system und verfahren zur verwendung davon
JP6305559B2 (ja) 2014-04-01 2018-04-04 華為終端(東莞)有限公司 セキュアエレメント管理方法及び端末
US10097619B2 (en) 2014-06-24 2018-10-09 Google Llc Cross-device notifications
US9960812B2 (en) 2014-11-14 2018-05-01 Qualcomm Incorporated Advanced routing mechanisms for secure elements
JP6706761B2 (ja) 2015-03-30 2020-06-10 パナソニックIpマネジメント株式会社 送信装置と、受信装置と、これらを備えた通信システム
US10366551B2 (en) * 2015-06-05 2019-07-30 Brivo Systems Llc Analytic identity measures for physical access control methods
JP2017010380A (ja) 2015-06-24 2017-01-12 パナソニックIpマネジメント株式会社 入退管理装置および入退管理方法
HK1251310A1 (zh) 2015-07-03 2019-01-25 阿费罗有限公司 用於在物联网(iot)系统中建立安全通信信道的设备和方法
CN105096420A (zh) * 2015-07-31 2015-11-25 北京旷视科技有限公司 门禁系统以及用于其的数据处理方法
WO2017031504A1 (en) * 2015-08-20 2017-02-23 Cloudwear, Inc. Method and apparatus for geographic location based electronic security management
US11282310B1 (en) * 2016-03-02 2022-03-22 Geokey, Inc. System and method for location-based access control
KR102098137B1 (ko) * 2016-04-15 2020-04-08 가부시키가이샤 덴소 실시간 로케이션을 설정하기 위한 시스템 및 방법
JP2019145854A (ja) 2016-06-27 2019-08-29 シャープ株式会社 基地局装置、端末装置およびその通信方法
CN106131015B (zh) 2016-07-13 2019-04-30 吴平 通过移动设备对附近目标设施进行权限操作
SG10201607277VA (en) * 2016-09-01 2018-04-27 Mastercard International Inc Method and system for access control
US10045184B2 (en) * 2016-11-11 2018-08-07 Carnival Corporation Wireless guest engagement system
US10719999B2 (en) * 2017-04-27 2020-07-21 Schlage Lock Company Llc Technologies for determining intent in an access control system
US10498538B2 (en) 2017-09-25 2019-12-03 Amazon Technologies, Inc. Time-bound secure access
US10679443B2 (en) * 2017-10-13 2020-06-09 Alcatraz AI, Inc. System and method for controlling access to a building with facial recognition
EP3752997B1 (de) * 2018-02-15 2025-02-12 Tyco Fire & Security GmbH Schussdetektionssystem mit umgebungsgeräuschmodellierung und -überwachung
US11373469B2 (en) * 2018-03-23 2022-06-28 Schlage Lock Company Llc Power and communication arrangements for an access control system
US10970949B2 (en) 2018-05-04 2021-04-06 Genetec Inc. Secure access control
US11205312B2 (en) * 2018-07-10 2021-12-21 Carrier Corporation Applying image analytics and machine learning to lock systems in hotels
CN109064599A (zh) 2018-07-27 2018-12-21 新华三技术有限公司 权限认证方法及装置
US11140175B2 (en) * 2018-12-19 2021-10-05 T-Mobile Usa, Inc. Multi-factor authentication with geolocation and short-range communication
KR20240105515A (ko) 2019-05-21 2024-07-05 에이치아이디 글로벌 코포레이션 물리적 액세스 제어 시스템 및 방법
WO2022101405A2 (en) 2020-11-13 2022-05-19 Assa Abloy Ab Secure element arrays in internet-of-things systems

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10185921B1 (en) * 2015-06-29 2019-01-22 Good2Go, Inc. Facility and resource access system

Also Published As

Publication number Publication date
EP4513457A2 (de) 2025-02-26
CN119030738A (zh) 2024-11-26
JP7544885B2 (ja) 2024-09-03
JP7274613B2 (ja) 2023-05-16
AU2025202560A1 (en) 2025-05-01
AU2025202562A1 (en) 2025-05-01
KR102680676B1 (ko) 2024-07-03
KR20240105515A (ko) 2024-07-05
CA3138776A1 (en) 2020-11-26
CN114679916B (zh) 2024-08-06
JP2022532932A (ja) 2022-07-20
AU2023219930B2 (en) 2025-01-16
WO2020236912A1 (en) 2020-11-26
CN114679916A (zh) 2022-06-28
AU2020280017A1 (en) 2021-12-16
KR20220021466A (ko) 2022-02-22
US12254732B2 (en) 2025-03-18
EP3973685C0 (de) 2025-02-19
AU2020280017B2 (en) 2023-05-25
JP2023062169A (ja) 2023-05-02
US20230252837A1 (en) 2023-08-10
EP3973685A1 (de) 2022-03-30
JP7835809B2 (ja) 2026-03-25
EP4513457A3 (de) 2025-05-07
JP2024161580A (ja) 2024-11-19
US20220230498A1 (en) 2022-07-21
AU2023219930A1 (en) 2023-09-14
MX2021014188A (es) 2022-02-11

Similar Documents

Publication Publication Date Title
AU2023219930B2 (en) Physical access control systems and methods
KR102612414B1 (ko) 액세스 제어를 위한 시스템들, 방법들, 및 디바이스들
KR102467468B1 (ko) 태그 인증과 결합된 생체 인식을 사용한 자동화된 물리적 액세스 제어 시스템에 대한 방법 및 시스템
KR20230020484A (ko) 비콘 신호를 이용하여 도어 출입을 관리하기 위한 방법 및 시스템
US20250022331A1 (en) Ultra-wide band radar for tailgating detection in access control systems
US11477181B2 (en) Network enabled control of security devices
KR102774964B1 (ko) 커맨드-응답 쌍을 이용한 인터페이스들에 대한 릴레이 공격 검출
CA3173957C (en) Ultra-wide band radar for tailgating detection in access control systems
EP4540798A1 (de) Änderung des kommunikationsmodus eines zugangssteuerungsprotokolls

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20211126

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: EXAMINATION IS IN PROGRESS

17Q First examination report despatched

Effective date: 20230831

REG Reference to a national code

Ref country code: DE

Ref legal event code: R079

Free format text: PREVIOUS MAIN CLASS: H04L0029060000

Ipc: H04W0012060000

Ref document number: 602020046304

Country of ref document: DE

RIC1 Information provided on ipc code assigned before grant

Ipc: G07C 9/00 20200101ALI20240220BHEP

Ipc: H04L 9/40 20220101ALI20240220BHEP

Ipc: H04W 12/06 20210101AFI20240220BHEP

GRAP Despatch of communication of intention to grant a patent

Free format text: ORIGINAL CODE: EPIDOSNIGR1

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: GRANT OF PATENT IS INTENDED

RIC1 Information provided on ipc code assigned before grant

Ipc: H04W 4/12 20090101ALN20240903BHEP

Ipc: G07C 9/00 20200101ALI20240903BHEP

Ipc: H04L 9/40 20220101ALI20240903BHEP

Ipc: H04W 12/06 20210101AFI20240903BHEP

INTG Intention to grant announced

Effective date: 20240917

GRAS Grant fee paid

Free format text: ORIGINAL CODE: EPIDOSNIGR3

GRAA (expected) grant

Free format text: ORIGINAL CODE: 0009210

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE PATENT HAS BEEN GRANTED

AK Designated contracting states

Kind code of ref document: B1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

REG Reference to a national code

Ref country code: GB

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: CH

Ref legal event code: EP

REG Reference to a national code

Ref country code: IE

Ref legal event code: FG4D

REG Reference to a national code

Ref country code: DE

Ref legal event code: R096

Ref document number: 602020046304

Country of ref document: DE

U01 Request for unitary effect filed

Effective date: 20250220

U07 Unitary effect registered

Designated state(s): AT BE BG DE DK EE FI FR IT LT LU LV MT NL PT RO SE SI

Effective date: 20250226

U20 Renewal fee for the european patent with unitary effect paid

Year of fee payment: 6

Effective date: 20250424

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: RS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250519

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: PL

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: ES

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IS

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250619

Ref country code: NO

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250519

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: HR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: GR

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250520

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SM

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: CZ

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: SK

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

REG Reference to a national code

Ref country code: CH

Ref legal event code: H13

Free format text: ST27 STATUS EVENT CODE: U-0-0-H10-H13 (AS PROVIDED BY THE NATIONAL OFFICE)

Effective date: 20251223

PLBE No opposition filed within time limit

Free format text: ORIGINAL CODE: 0009261

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: CH

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20250531

26N No opposition filed

Effective date: 20251120

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: MC

Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT

Effective date: 20250219

PGFP Annual fee paid to national office [announced via postgrant information from national office to epo]

Ref country code: GB

Payment date: 20260312

Year of fee payment: 7

PG25 Lapsed in a contracting state [announced via postgrant information from national office to epo]

Ref country code: IE

Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES

Effective date: 20250520